How did the Moonwell exploit on Base drain $8.7 million without a code hack?

The Moonwell protocol on the Base network lost $8.7 million after an attacker manipulated MAMO collateral pricing to borrow cbBTC and USDC. This incident demonstrates how economic vulnerabilities can be exploited in DeFi even when the underlying smart contract code remains secure.
How did the Moonwell exploit on Base drain $8.7 million without a code hack?

The Moonwell protocol, a leading decentralized lending platform on the Base network, suffered an $8.7 million drain due to a price manipulation exploit rather than a traditional smart contract breach. By artificially inflating the collateral value of the MAMO token, an attacker was able to borrow excessive amounts of cbBTC (Coinbase Wrapped BTC) and USDC. This allowed the perpetrator to withdraw high-value assets while leaving behind overvalued and illiquid collateral, effectively emptying the protocol's liquidity pools.

Security researchers confirmed that the incident did not involve a single line of code being hacked or a bug in the protocol's logic. Instead, the attacker targeted the pricing mechanism used to value MAMO within the Moonwell ecosystem. By manipulating the market price or the oracle feed responsible for reporting that price, the attacker tricked the platform into believing their deposits were worth significantly more than their true market value, bypassing standard borrowing limits.

This event highlights a growing trend in DeFi exploits where 'economic logic' is the primary target. For US-based users on Base—a network incubated by Coinbase—the loss of cbBTC is particularly notable, as it involves the flagship wrapped Bitcoin product intended for secure institutional and retail use. Such incidents often attract the attention of US regulators like the CFTC and SEC, who argue that decentralized platforms lack the necessary guardrails to protect participants from market manipulation.

Market participants should watch for Moonwell’s post-mortem report and any potential governance proposals to reimburse affected users or tighten collateral requirements. The protocol will likely need to integrate more resilient oracle solutions and implement stricter 'price impact' checks to prevent similar attacks. For the broader market, this serves as a cautionary tale about the risks of using low-liquidity assets as collateral in lending markets, potentially leading to more conservative listing policies across the DeFi sector.